Linux 7.4 is set to gain a slab_tiny boot option that replaces the compile-time CONFIG_SLUB_TINY, letting one kernel image serve both small-memory and full-size boards, alongside a sheaves refill patch worth 24% on an mmap microbenchmark. Security researchers demonstrated that inotify leaks keystroke timing and authentication-prompt timing; the kernel’s partial fix is already in the longterm series. Linux 7.3 reached rc5 with a final release projected for mid-October, and the 7.1 series is now end-of-life. RK3588 mainline video decoding is moving towards dual-core operation, and the kernel may gain an AGENTS.md file for AI coding agents.
This edition has a common direction: decisions are moving to where they can still be changed. The memory allocator’s small-system mode is moving from build time to boot time, a security fix closes an interface that reported more than anyone intended, and the development process is being adjusted for the tools that now submit and review patches. For embedded teams, three of the five items feed directly into base-kernel planning for the next twelve months.
In this edition
- A slab_tiny boot option is queued for 7.4 — CONFIG_SLUB_TINY is set to be replaced by a runtime parameter, and a small sheaves patch delivers a 24% microbenchmark gain. — planning signal
- inotify shown to leak keystroke and authentication timing — watch permission on a directory is enough; the partial kernel fix already sits in the longterm series. — check your device
- 7.3 at rc5, final projected for 18 October; 7.1 is end-of-life — large but unalarming release candidates, and a base-kernel decision for anyone still on 7.1. — plan your base kernel
- RK3588 mainline video decoding: merged codecs and the dual-core road — H.264 and HEVC decode has been upstream since 7.0; the second decoder core is the next step. — long-term watch
- AGENTS.md proposed for the kernel tree — a file to point AI coding agents at the kernel’s own rules, and a disagreement about how much they should read. — process watch
The slab_tiny boot option: small-system allocator mode moves to run time
Vlastimil Babka, the slab maintainer, posted an eight-patch series on 23 September that replaces CONFIG_SLUB_TINY with a slab_tiny boot option. The compile-time Kconfig switch is deprecated; the same kernel binary decides at boot whether to run the allocator in its minimal-footprint mode. The series also converts slab_debug handling and is aimed at the 7.4 merge window.
CONFIG_SLUB_TINY arrived in Linux 6.2 as part of deprecating the old SLOB allocator, which was removed soon after. It trades allocation throughput for lower memory overhead, which is why it appears in defconfigs for boards in the tens-of-megabytes class. The cost until now has been a separate kernel build: a distribution or BSP that wanted the tiny behaviour had to ship a second image.
That cost is what the change removes. One image can boot with slab_tiny on a 64 MB industrial controller and without it on a 4 GB module, and the choice can be tested by editing the kernel command line instead of rebuilding. The same week brought a performance patch at the other end of the allocator: Hao Li’s 81-line change lets prefilled sheaves — the per-CPU object caches SLUB gained recently — refill directly from the “barn”, the shared store of full sheaves, instead of always going back to partial slabs. On the will-it-scale mmap1 test the patch raises throughput 24.2%, from 27.8 to 34.5 million operations, and cuts failed barn returns by 44%. It carries Reviewed-by tags from Harry Yoo and from Babka and is queued in the slab tree for 7.4.
Taken together the direction is clear: with the slab_tiny boot option at one end and sheaves tuning at the other, the allocator is becoming one code base whose behaviour is chosen and tuned at run time, from very small systems to very parallel ones.
What it means for BSP maintainers
If any of your defconfigs set CONFIG_SLUB_TINY=y, follow this series: once it lands, a config refresh will drop the symbol and the behaviour will need to be carried in the bootargs of your device tree or bootloader environment instead. The consolidation is an opportunity — image variants that existed only for the allocator choice can be merged. Before enabling the slab_tiny boot option on existing products, measure with your own workload; the tiny mode’s throughput cost is real and always has been, and it is now cheap to A/B test because no rebuild is involved.
inotify is a side channel: keystroke timing with no read access
Researchers at Graz University of Technology, in a team including Sudheendra Raghav Neela and Daniel Gruss, have shown that file-notification interfaces on all major operating systems can be used to reconstruct user behaviour. The paper is accepted at ACM CCS 2026 in November. The core finding is that watch permission on a directory is sufficient — no read access to any file’s contents is required — to observe when other users type, browse or authenticate.
On Linux the attacks use inotify. Watching device nodes under /dev/input yields inter-keystroke timing. A second demonstration targets KDE Plasma: watching /usr/bin/pkexec reveals the moment Polkit spawns an authentication dialog, precisely enough to overlay a fake password prompt. The same class of attack works through Android’s FileObserver, where message-arrival activity in application folders becomes visible, and through the Windows and macOS equivalents; on Windows, the researchers fingerprinted browsing across the top thousand websites with an F1 score of 97.8%.
The kernel side is partly fixed. The commit “fsnotify: do not generate ACCESS/MODIFY events on child for special files” stops parent-directory watchers from receiving access and modify events for character devices and other special files, closing the /dev/input path. It is tracked as CVE-2025-68788; the kernel CVE announcement of 13 January lists the fix in mainline 6.19-rc2 and in 6.1.160, 6.6.120, 6.12.64 and 6.18.3, and the researchers additionally list 5.15.198 and 5.10.248 for the older longterm series. The mitigation is partial by design: notification timing on regular files is the interface working as specified, so the broader channel remains.
How to check your device
The exposure matters wherever untrusted code shares a kernel with users: multi-user systems, kiosks, and containers on shared embedded hosts. Compare your running kernel against the fix versions for its series:
raghu@techveda.org:~$ uname -rA 6.12 kernel needs 6.12.64 or later; 6.6 needs 6.6.120; 6.1 needs 6.1.160; 6.18 needs 6.18.3. Vendor BSP kernels that stopped taking stable updates will not have the fix regardless of series. To see which processes on a device hold inotify watches at all:
raghu@techveda.org:~$ sudo find /proc/[0-9]*/fdinfo -type f 2>/dev/null | xargs grep -l inotify 2>/dev/null | cut -d/ -f3 | sort -uThe output is a list of PIDs. On a locked-down device that list should be short and explainable; anything unexpected watching /dev or system binaries deserves a closer look.
7.3 at rc5 and on schedule; the 7.1 series is finished
Linux 7.3-rc5 was released on 27 September with 577 commits. The release candidates this cycle have been consistently large, and rc5’s shape was unusual — drivers under a third of the diff, selftests around a quarter — but Linus Torvalds called the content routine and said nothing looks alarming. The fixes concentrate in KVM and perf, the scheduler and BPF, networking drivers and DRM, and HID++ support for the Logitech Bolt receiver was reverted after problems.
If the usual seven release candidates hold, 7.3 ships on 18 October; an eighth would push it to 25 October. Those dates are projections from the cadence, not announcements. The 7.4 merge window opens immediately after the release, which is when the slab work above, the parallelised kernel build series and the other queued 7.4 material would land.
The same week closed a chapter: with 7.1.13, the 7.1 series is end-of-life on kernel.org. The 25 September stable updates were 7.2.8 and 6.18.54, and the longterm lines 6.12, 6.6, 6.1, 5.15 and 5.10 all saw releases earlier in the month. A product tracking 7.1 now has no upstream security path.
What it means for release planning
Teams on a 7.1-based kernel should treat the move as due now, not at the next convenient milestone: 7.2 is the short-lived option, and 6.18 or 6.12 are the longterm ones. Teams planning new platforms around 7.3 can start validation against rc5, since late rcs rarely change interfaces. And anything you intend to land upstream in 7.4 needs to be in a maintainer tree in the next three weeks.
RK3588 video decoding in mainline: what is merged and what the second core needs
At Kernel Recipes in Paris on 21–23 September, Detlev Casanova of Collabora presented the state of upstream video decoding for Rockchip’s RK3588 and RK3576.
The foundation is already in place. Linux 7.0 merged H.264 and HEVC decoding for the RK3588’s VDPU381 and the RK3576’s VDPU383 as part of the rkvdec driver, implementing the V4L2 stateless decode API. The 17-patch series brought new UAPI controls for HEVC reference-picture-set handling and solved an awkward platform problem — the decoder resets its embedded IOMMU, which the IOMMU framework had to learn to recover from. GStreamer 1.28 and FFmpeg already consume the stateless API, so the merged support is usable from ordinary media pipelines.
The talk’s subject is the next step. The RK3588 carries two VDPU381 cores, and multi-core scheduling is not yet enabled upstream, so mainline currently decodes on one core. VP9 support exists in preliminary form, AV1 on the RK3576 is earlier still, and the older VDPU346 on RK356x parts is a separate effort. Dual-core operation is what would bring mainline decode throughput to parity with the vendor stack on high-bitrate 4K content.
How to evaluate it
If your RK3588 product carries the vendor 6.1 BSP mainly for video, re-test your actual codec mix on a 7.x kernel: H.264 and HEVC pipelines through GStreamer are the supported path today, while VP9 or AV1 content still requires the vendor stack. Measure single-core decode against your worst-case streams before deciding whether you must wait for multi-core support. A product that passes on one core can plan its mainline migration now and treat the second core as future headroom rather than a blocker.
AGENTS.md: telling AI agents where the kernel’s rules are
Sasha Levin posted a patch on 24 September adding an AGENTS.md file to the kernel tree — the convention several AI coding tools read on startup — pointing agents at the kernel’s README and the existing submission documentation rather than duplicating any of it. His stated motivation is practical: in testing without the file, agents mis-attributed their work, one adding a Signed-off-by tag it had no right to and another inventing an attribution tag instead of using the kernel’s Assisted-by convention; with the file present, the same agents followed the rules.
The objections on the list are practical too. Making every agent ingest the full documentation on every run costs context and tokens, and several developers argued for a smaller, purpose-written file for machine consumption instead. The discussion is unresolved, and it continues this year’s run of process adaptations for automated contributors.
The substance here is not the file itself but what it acknowledges: patch submission norms are now written for tools as well as people, and the kernel is choosing to steer the tools rather than pretend they are not present.
How to use it
The pattern transfers directly to private trees. If your team runs AI assistants against a BSP or internal kernel fork, add a repository-level agent instruction file that points at your own contribution rules — coding style, commit-message format, sign-off policy, and which subsystems are off-limits. Enforce the attribution convention in review regardless of tooling: the kernel’s Assisted-by practice is a reasonable template to copy.
References
- slab: replace CONFIG_SLUB_TINY with a slab_tiny boot parameter (patch series)
- “slab_tiny” boot option proposed for tiny Linux systems
- mm/slub: refill prefilled sheaves from the barn (list mirror)
- MM change slated for Linux 7.4
- File Notification Attacks (research site)
- Research into file-notification attacks on Linux
- CVE-2025-68788 announcement
- kernel.org releases
- Linux 7.3-rc5 released
- Linux 7.3-rc5 details
- RK3588 and RK3576 video decoders merged upstream
- Decoding with Rockchip at Kernel Recipes 2026
- RK3588/RK3576 decoders in mainline Linux
- Linux kernel developers consider adding AGENTS.md
— Raghu Bharadwaj




